Site navigation

Report: UK Political Donation Sites Pose Major Cybersecurity Risk

Elizabeth Greenberg

,

uk political donations security
Following the 2024 general election, a review of political donation sites found major gaps in their security measures. 

Donation sites used by the seven major UK political parties during the recent 2024 elections lacked key critical security measures, a review has found.

Donors looking to help fund political parties often provide personal and financial information, including as names, addresses, and credit card details. Securing this information is critical in preventing identity theft and financial fraud – yet donation portals representing political parties are failing to protect their supporters.

This is according to analysis from DataDome, which looked into the security measures used by the UK’s seven major political parties (Labour, Conservatives, Liberal Democrats, SNP, Green Party, Plaid Cymru, and Reform UK).

Researchers found that all lacked critical security measures, with only three sites – Plaid Cymru, SNP, and Reform UK having a login endpoint. Regardless of this feature, however, every site was missing critical features to protect against bots and credential stuffing attacks.

DataDome claims it was even able to create a bot capable of successfully logging into an account it had made without any security measures countering it.

Only two of the sites, Labour and SNP, used reCaptcha, a feature to weed out bots, and even then they only use to security feature on account creation pages rather than on login pages. The use of CAPTCHA alone leaves these sites still vulnerable to bots.

The lack of robust or even basic security measures can expose user accounts to credential stuffing attacks, which can lead to unauthorised account access, allowing attackers to harvest personal information and stored credit card data.

Further, if users saved their payment card information for recurring donations, then they are at an increased risk of financial theft and data breaches due to a lack of security measures.


Recommended reading


The heightened risk of a data breach could also lead to significant reputational damage, potentially eroding donor trust and impacting future fundraising efforts.

Following the revelations, DataDome urged donantion platforms to take extra security steps before the next round of local elections set to take place in 2025.

Deploying two-factor authentication and employing advanced bot protection were just two measures the platforms were urged to adopt.

Donors are also warned to shore up their protection efforts by using a strong and unique password to mitigate the effectiveness of a credential stuffing attempt.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data